fix(client/auth): tolerate comma-separated scope strings - #3568
dgilman-perplexity wants to merge 1 commit into
Conversation
RFC 6749 §3.3 separates scopes with spaces, but real-world authorization servers (e.g. Linear) return comma-separated scope lists in token responses and WWW-Authenticate challenges. Scope membership checks and the SEP-2350 step-up union split on whitespace only, so a comma-separated grant is treated as a single opaque scope: unions stop deduplicating and offline_access handling misfires. Add a parse_scopes helper accepting both separators and use it in union_scopes and the offline_access membership checks. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
This PR has been closed automatically. It's still a draft, but we close those early so you don't put in more time only to have it closed the moment you mark it ready. This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and you aren't currently assigned to #3566. If a maintainer assigns you to #3566, this PR reopens on its own and there's nothing more you need to do here. Assignment is a maintainer call based on capacity; comments that only ask to be assigned don't factor in. What does help is engaging on the issue itself by confirming the repro, explaining why it matters for your use case, or describing the approach you'd take. You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way. CONTRIBUTING.md has the full reasoning, but in short:
Maintainers: reopen, remove |
Fixes #3566.
Motivation
RFC 6749 §3.3 separates scopes with spaces, but real-world authorization servers (e.g. Linear) return comma-separated
scopevalues in token responses andWWW-Authenticatechallenges. Scope membership checks and the SEP-2350 step-up union split on whitespace only, so a comma-separated grant is treated as a single opaque scope: unions stop deduplicating (scopes accumulate asread,write read write) andoffline_access/prompt=consenthandling misfires.Change
Adds a
parse_scopeshelper that accepts both space and comma separators and uses it inunion_scopesand the twooffline_accessmembership checks. The join side is unchanged — the client always emits space-separated scope strings. Parametrized tests for the helper and a comma-input case forunion_scopesincluded.🤖 Generated with Claude Code